
German industrial group Siemens has confirmed that a virus has been detected which explicitly targets industrial command and control systems in which the company specialises.
The malware, dubbed Stuxnet, is spread via USB devices, which is a common way of updating manufacturing hardware. The software is designed to steal data on manufacturing and industrial processes and pass the data on to third parties.
“What is unique about Stuxnet is that it utilizes a new method of propagation,” said Tareq Saade from Microsoft Malware Protection Center.
“Specifically, it takes advantage of specially-crafted shortcut files (also known as .lnk files) placed on USB drives to automatically execute malware as soon as the .lnk file is read by the operating system. In other words, simply browsing to the removable media drive using an application that displays shortcut icons (like Windows Explorer) runs the malware without any additional user interaction.”
Siemens has reportedly said that only one customer has been infected so far, but that it keeping a watch on further incidents.
